Back to directory
WRITEUP #3897

OAuth Misconfiguration found in small time-window of attack

OAuth
by@Muhammad__Aamir(Muhammad Aamir)
Bounty
300
Program
-
Published
Mar 20, 2021
Added to HackDex
Sep 15, 2022
Read Full Writeuphttps://muhammad-aamir.medium.com/oauth-misconfiguration-found-in-small-time-window-of-attack-b585afcb94c6
RELATED WRITEUPS
How I Got $250 For My Second Bug on HackerOne
OAuthSession expiration issue
AI Under Siege: Discovering and Exploiting Vulnerabilities
AI / LLMAI
Stealing First Party Access Token of Facebook Users: Meta Bug Bounty
OAuthAccount takeover
Over 1 Million websites are at risk of sensitive information leakage - XSS is dead. Long live XSS
XSSOAuth
Self XSS + Login CSRF + OAuth = Account Takeover
Auth BypassAccount takeover

Built with ❤️ by Shubham Rawat